ÀÕË÷Èí¼þ¿ª·¢Õß¹ûÕæEgregor¡¢MazeºÍSekhmetµÄÖ÷ÃÜÔ¿

Ðû²¼Ê±¼ä 2022-02-14

ÀÕË÷Èí¼þ¿ª·¢Õß¹ûÕæEgregor¡¢MazeºÍSekhmetµÄÖ÷ÃÜÔ¿


¾ÝýÌå2ÔÂ8ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ £¬ÀÕË÷Èí¼þMaze¡¢EgregorºÍSekhmetµÄÖ÷½âÃÜÃÜÔ¿Òѱ»¹ûÕæ¡£¡£¡£¡£¡£¡£¡£ÃûΪ¡°Topleak¡±µÄÓû§ÔÚBleepingComputerÂÛ̳ÉÏÐû²¼ÁËÒ»¸ö7zipÎļþµÄÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬ £¬ÆäÖаüÀ¨ Maze¡¢EgregorºÍSekhmet½âÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÀÕË÷ÍÅ»ïʹÓõĶñÒâÈí¼þ¡°M0yv¡±µÄÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£ËûÉù³Æ×Ô¼ºÊÇÕâ3¸ö¶ñÒâÈí¼þµÄ¿ª·¢Õߣ¬£¬£¬£¬£¬£¬ £¬²¢ÌåÏÖÕâÊÇÒ»´ÎÓÐÍýÏëµÄ¹ûÕæ£¬£¬£¬£¬£¬£¬ £¬Óë½üÆÚµÄÖ´·¨Ðж¯Î޹ء£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ransomware-dev-releases-egregor-maze-master-decryption-keys/


HP·¢Ã÷¹¥»÷Õß½«RedLineαװ³ÉWindows 11µÄÉý¼¶³ÌÐò


HPÑо¿ÍŶÓÔÚ2ÔÂ8ÈÕÅû¶ÁË·Ö·¢RedLineµÄ»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£1ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±×¢Öص½¹¥»÷Õß×¢²áÁËÓòwindows-upgraded[.]com¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾Ä£ÄâÁËÕæÕýµÄWindows 11¹ÙÍø£¬£¬£¬£¬£¬£¬ £¬Óû§µã»÷¡°Á¬Ã¦ÏÂÔØ¡±°´Å¥£¬£¬£¬£¬£¬£¬ £¬¾Í»áÏÂÔØÍйÜÔÚDiscord CDNÉϾÞϸΪ1.5MBµÄZIPÎļþ¡°Windows11InstallationAssistant.zip¡±¡£¡£¡£¡£¡£¡£¡£½âѹ²¢Ö´Ðк󣬣¬£¬£¬£¬£¬ £¬»á´ÓÔ¶³ÌWebЧÀÍÆ÷ÏÂÔØÃûΪwin11.jpgµÄÎļþ£¬£¬£¬£¬£¬£¬ £¬ÆäÖаüÀ¨RedLineµÄpayload¡£¡£¡£¡£¡£¡£¡£


https://threatresearch.ext.hp.com/redline-stealer-disguised-as-a-windows-11-upgrade/


ÒÁÀʺڿÍÔÚÌØ¹¤»î¶¯Out to SeaÖÐʹÓÃкóÃÅMarlin


¾Ý2ÔÂ9ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ £¬Çå¾²¹«Ë¾ESET·¢Ã÷ÁËÒÁÀʺڿÍÔÚ½üÆÚ¹¥»÷ÖÐʹÓÃеÄMarlinºóÃÅ¡£¡£¡£¡£¡£¡£¡£ESETÌåÏÖ£¬£¬£¬£¬£¬£¬ £¬´Ë´ÎÌØ¹¤»î¶¯Out to Sea×Ô2018Äê4Ô¾ÍÒÑ×îÏÈ£¬£¬£¬£¬£¬£¬ £¬Ê¹ÓÃеÄMarlinÖ÷ÒªÕë¶ÔÒÔÉ«ÁС¢Í»Äá˹ºÍ°¢À­²®ÁªºÏÇõ³¤¹úµÄÍâ½»×éÖ¯¡¢¿Æ¼¼¹«Ë¾ºÍÒ½ÁÆ×éÖ¯µÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ £¬»¹½«´Ë´ÎµÄ¹¥»÷»î¶¯¹éÒòÓÚOilRig£¨ÓÖÃûAPT34£©£¬£¬£¬£¬£¬£¬ £¬×îÖÕ»¹½«Æä»î¶¯ÓëÁíÒ»¸öÒÁÀÊ×éÖ¯LyceumÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/02/iranian-hackers-using-new-marlin.html


Qualys·¢Ã÷Lazarusð³äLockheed MartinµÄ´¹Âڻ


2ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬ £¬QualysÅû¶Á˳¯ÏÊÍÅ»ïLazarus½üÆÚ¿ªÕ¹µÄ´¹ÂڻLolZarusµÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶Ô¹ú·ÀÐÐÒµµÄÇóÖ°Õߣ¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õßð³äÁËLockheed Martin¹«Ë¾ÏòÄ¿µÄ·¢ËÍ´¹ÂÚÎļþ£¬£¬£¬£¬£¬£¬ £¬Ã°³äÌṩ¾Íҵʱ»ú¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÃÀ¹úµÄÒ»¼Ò¹ú·À¿Æ¼¼¹«Ë¾£¬£¬£¬£¬£¬£¬ £¬ÔÚ2020ÄêµÄÏúÊÛ¶îΪ654ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ £¬¸Ã»î¶¯»¹Ê¹ÓÃÁ˲î±ðµÄlolbin¡£¡£¡£¡£¡£¡£¡£Õâ²»ÊÇLazarusµÚÒ»´ÎʹÓôËÀàÓÕ¶ü£¬£¬£¬£¬£¬£¬ £¬ËüÔøÎ±×°³ÉNorthrop GrummanºÍBAE Systemsð³äÌṩ¾Íҵʱ»ú¡£¡£¡£¡£¡£¡£¡£


https://www.zdnet.com/article/lazarus-hackers-target-defense-industry-with-fake-lockheed-martin-job-offers/


KasperskyÐû²¼2021ÄêÀ¬»øÓʼþºÍ´¹ÂڻµÄ±¨¸æ


2ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬ £¬KasperskyÐû²¼ÁË2021ÄêÀ¬»øÓʼþºÍ´¹ÂڻµÄ±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ £¬ÔÚ2021Ä꣬£¬£¬£¬£¬£¬ £¬56%µÄµç×ÓÓʼþÊÇÀ¬»øÓʼþ£»£»£»£»×î¶àµÄÀ¬»øÓʼþÀ´×Ô¶íÂÞ˹£¨24.77%£©£¬£¬£¬£¬£¬£¬ £¬Æä´ÎÊǵ¹ú£¨14.12%£©£»£»£»£»Î÷°àÑÀÔâµ½µÄ¶ñÒâÓʼþ¹¥»÷×î¶à£¬£¬£¬£¬£¬£¬ £¬Îª9.32%£¬£¬£¬£¬£¬£¬ £¬Æä´ÎÊǶíÂÞ˹£¨6.33%£©£»£»£»£»Ôâµ½´¹ÂÚ¹¥»÷×î¶àµÄ¹ú¼ÒÊǰÍÎ÷£¨12.39%£©£¬£¬£¬£¬£¬£¬ £¬Æä´ÎÊÇ·¨¹ú£¨12.21%£©£»£»£»£»¸½¼þÖÐ×î³£¼ûµÄ¶ñÒâÈí¼þ¼Ò×åÊÇAgenslaľÂí¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/spam-and-phishing-in-2021/105713/


AppleÐÞ¸´Òѱ»Ê¹ÓõÄÊͷźóʹÓÃÎó²îCVE-2022-22620


AppleÔÚ2ÔÂ10ÈÕÐû²¼¸üУ¬£¬£¬£¬£¬£¬ £¬ÐÞ¸´ÁËÒ»¸öWebKitµÄÊͷźóʹÓÃÎó²îCVE-2022-22620¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܻᵼÖ²Ù×÷ϵͳÍß½âºÍÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐдúÂ룬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒÑÔÚÒ°ÍâʹÓÃËüÈëÇÖiPhone¡¢iPadºÍMac¡£¡£¡£¡£¡£¡£¡£Appleͨ¹ýË¢ÐÂiOS 15.3.1¡¢iPadOS 15.3.1ºÍmacOS Monterey 12.2.1ÖеÄÄÚ´æÖÎÀíÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚÈý¸ö0 day£¬£¬£¬£¬£¬£¬ £¬Ç°Á½¸öΪCVE-2022-22587ºÍCVE-2022-22594¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/apple-patches-new-zero-day-exploited-to-hack-iphones-ipads-macs/


Çå¾²¹¤¾ß


Merry-Maker


ΪÁË×èÖ¹ÈÕÒæÔö¶àµÄÕë¶Ôµç×ÓÊÐËÁµÄÍøÂçä¯ÀÀ¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬ £¬Target¿ªÔ´ÁËÒѾ­ÓɲâÊÔµÄɨÃ蹤¾ß¡£¡£¡£¡£¡£¡£¡£


https://latesthackingnews.com/2022/02/09/merry-maker-card-skimmer-scanner-tool-released-as-open-source/


Second Order 


ͨ¹ýץȡӦÓóÌÐò²¢ÍøÂçÇкÏÌØ¶¨¹æÔò»òÒÔÌØ¶¨·½·¨ÏìÓ¦µÄ URL£¨ºÍÆäËûÊý¾Ý£©À´É¨Ãè Web Ó¦ÓóÌÐòÒÔ¾ÙÐжþ¼¶×ÓÓò½ÓÊÜ¡£¡£¡£¡£¡£¡£¡£


https://github.com/mhmdiaa/second-order


whatfiles


Linux ÊÊÓóÌÐò£¬£¬£¬£¬£¬£¬ £¬Ëü¼Í¼ÁíÒ»¸ö³ÌÐòÔÚϵͳÉ϶ÁÈ¡/дÈë/½¨Éè/ɾ³ýµÄÎļþ£¬£¬£¬£¬£¬£¬ £¬»¹¸ú×ÙÄ¿µÄÀú³Ì½¨ÉèµÄÈκÎÐÂÀú³ÌºÍÏ̡߳£¡£¡£¡£¡£¡£¡£


https://github.com/spieglt/whatfiles


logdata anomaly miner


¸Ã¹¤¾ßÆÊÎöÈÕÖ¾Êý¾Ý²¢ÔÊÐíΪÒì³£¼ì²â½ç˵ÆÊÎö¹ÜµÀ£¬£¬£¬£¬£¬£¬ £¬Ö¼ÔÚÒÔÓÐÏÞµÄ×ÊÔ´ºÍ¾¡¿ÉÄܵ͵ÄȨÏÞÔËÐÐÆÊÎö¡£¡£¡£¡£¡£¡£¡£


https://github.com/ait-aecid/logdata-anomaly-miner


extrude


ÆÊÎö¶þ½øÖÆÎļþÊÇ·ñȱÉÙÇå¾²¹¦Ð§¡¢ÐÅϢй¶µÈ¡£¡£¡£¡£¡£¡£¡£


https://github.com/liamg/extrude/


Çå¾²ÆÊÎö


FederalÐû²¼Éí·ÝڲƭµÖÓù¹¤¾ß°üÒÔ×ÊÖúÆóÒµ¹¥»÷ڲƭ


https://www.helpnetsecurity.com/2022/02/10/federal-reserve-synthetic-identity-fraud-mitigation-toolkit/


PHP Everywhere RCE Îó²îÍþв×Å´ó×ÚµÄ WordPress ÍøÕ¾


https://thehackernews.com/2022/02/critical-rce-flaws-in-php-everywhere.html


Apple ÒâÍâ±£´æ²¿·Ö iPhone É쵀 Siri ¼Òô


https://blog.malwarebytes.com/opinion/2022/02/apple-accidentally-kept-some-siri-recordings-from-iphones-even-for-opted-out-users/


Meta ºÍ Chime ÆðËß2¸öÄáÈÕÀûÑÇÈËʹÓà Facebook¡¢Instagram ´¹ÂÚ


https://www.bleepingcomputer.com/news/security/meta-and-chime-sue-nigerians-behind-facebook-instagram-phishing/


FBI ÖÒÑÔÉý¼¶µÄ SIM ¿¨½»Á÷¹¥»÷ÇÔÈ¡Êý°ÙÍòÃÀÔª


https://www.bleepingcomputer.com/news/security/fbi-warns-of-criminals-escalating-sim-swap-attacks-to-steal-millions/